DocumentCode :
1681056
Title :
An overlay protection layer against Denial-of-Service attacks
Author :
Beitollahi, Hakem ; Deconinck, Geert
Author_Institution :
Electr. Eng., Katholieke Univ. Leuven, Leuven
fYear :
2008
Firstpage :
1
Lastpage :
8
Abstract :
Today Internet is becoming an emerging technology for remote control of industrial applications, where one site needs to control another site remotely (e.g. power plants controllers). Denial-of-Service (DoS) attacks may cause significant disruptions to the Internet which will threaten the operation of such network based control systems. Overlay networks have been proposed to protect Internet application sites by location-hiding technique. This paper analyzes a large domain of previous approaches against this problem. This paper addresses how an interface to an overlay network can be designed such that communication services among geographically distributed application sites are secured against DoS attacks. This paper presents a novel architecture called overlay protection layer (OPL) that proactively protect application sites from DoS attacks. Through simulation this paper shows DoS attacks have a negligible chance to disrupt communications services via the OPL architecture. Even if attackers attack 50% of overlay nodes via a Distributed DoS attack still 75% of communication channels are available.
Keywords :
Web services; security; Internet; communication services; denial of service attacks; network based control systems; overlay protection layer; Communication channels; Communication system control; Computer crime; Control systems; Electrical equipment industry; IP networks; Industrial control; Internet; Power generation; Power system protection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Parallel and Distributed Processing, 2008. IPDPS 2008. IEEE International Symposium on
Conference_Location :
Miami, FL
ISSN :
1530-2075
Print_ISBN :
978-1-4244-1693-6
Electronic_ISBN :
1530-2075
Type :
conf
DOI :
10.1109/IPDPS.2008.4536157
Filename :
4536157
Link To Document :
بازگشت